Event-Driven Ansible Server Vulnerability Exposing API Access Controls
CVE-2026-12383

7.5HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
27 July 2026

What is CVE-2026-12383?

A security flaw exists in the Event-Driven Ansible (EDA) server where the ExternalEventStreamViewSet has permissive access controls, allowing unrestricted access for unauthenticated requests. It relies solely on the Subject HTTP header value for mutual TLS (mTLS) authentication, failing to confirm the header's origin from a trusted proxy. This oversight enables an attacker to reach the EDA API endpoint using a spoofed Subject header, potentially injecting arbitrary events into mTLS-protected event streams. Furthermore, the expected certificate Distinguished Name is inadvertently exposed in the response body of 403 error messages, enhancing the risk of exploitation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Chris Meyers (Red Hat).
.